GCIH Malware and AI-Assisted Investigations Practice Question
Which of the following is the primary risk associated with using unvetted AI models for malware signature generation?
⚠ Common exam trap
Candidates often identify 'AI model theft' or 'slow processing' as the primary risk, overlooking the operational disaster of a false-positive signature that disables critical business services and system binaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The model may produce signatures that trigger on benign system binaries.
Using unvetted AI models for signature generation risks creating false signatures that could lead to widespread system instability or denial of service if deployed to endpoint protection platforms. In the context of malware investigation, these tools must be calibrated against known-good and known-bad datasets. Failing to vet the model results in a high false-positive rate, which ultimately undermines the efficacy of the incident response team and wastes valuable time during critical security incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The model will always generate signatures that are too complex to implement.
Why it's wrong here
The primary risk is not the complexity of the signature but its accuracy. An overly complex signature might be harder to maintain, but an inaccurate signature is fundamentally damaging to the security posture. AI models can just as easily generate simple, incorrect signatures that lead to high rates of false negatives or positives.
- ✓
The model may produce signatures that trigger on benign system binaries.
Why this is correct
AI models trained on insufficient or biased data often fail to distinguish between malicious and legitimate system activity. This leads to the generation of false-positive signatures that flag critical OS files. Deploying such signatures in a production environment causes significant operational disruption, effectively creating a self-inflicted denial-of-service attack for the organization.
- ✗
The model will consume excessive processing power on the endpoint.
Why it's wrong here
While AI models can be resource-intensive, the primary risk for an incident handler is the validity of the detection, not the CPU utilization. Security tools are designed to manage performance, but no amount of optimization can compensate for a detection capability that incorrectly flags benign software, causing operational chaos.
- ✗
The model will force the malware to evolve into a polymorphic variant.
Why it's wrong here
Malware evolution is driven by the attacker's intent and development, not by the detection signatures generated by the responder. While defenders' actions may influence attacker tactics, the signature generation process itself does not directly 'force' malware to change its underlying polymorphic capabilities in real-time response scenarios.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.